From system state to defensible evidence

Evidence Collection

Choose a proportionate collection method, minimise unnecessary change, and preserve enough context for another analyst to understand and verify the evidence.

3collection routes9practical tools1traceable record
01

Follow a defensible workflow

Select each stage to see how collection decisions protect evidence value.

Stage 1Define the question and authority

Record the system, owner, time range, investigation question, and actions you are authorised to perform.

Ask: What decision must this evidence support?
02

Choose the collection path

Start with the evidence that best answers your question, not the tool with the longest feature list.

Best matchStart with live response and triage

Collect targeted system state and high-value artefacts while the computer is running.

03

Build your foundation

Learn the decision-making behind each collection route before using the tools.

04

Choose a tool by collection need

Select the evidence need first. The recommendation points to one practical starting guide.

Best starting point for targeted triageKAPE

Collect and process selected forensic artefacts quickly using repeatable targets and modules.

Also consider Velociraptor for remote collection or Kansa for PowerShell-led triage across Windows systems.
Explore KAPE
05

Check collection readiness

Confirm the basics before acquiring evidence from a real or simulated system.

!
Preparation required5 checks remaining.